| File name: | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer |
| Full analysis: | https://app.any.run/tasks/2580d0c8-e835-4022-ab4e-c05add2812d0 |
| Verdict: | Malicious activity |
| Analysis date: | July 06, 2025, 01:13:26 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 34F234D8198274D4424D880395647A0B |
| SHA1: | 581F88A0D1B59782B6190F7485AE975A347F10F9 |
| SHA256: | A8E67C54A628621E6F5001EF2914ECB346F6EA9390C3FC648BC6B2CF91DB64E0 |
| SSDEEP: | 98304:HSxvRGu7ZRfiObci3rs7Rge4yM9WqvXvByLwGNP9hshSa06wsS+jUQOnXIrVj6Qd:Kya8sD |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:07:05 01:31:34+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.43 |
| CodeSize: | 160256 |
| InitializedDataSize: | 131584 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xc120 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4528 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5020 | "C:\Users\admin\Desktop\2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe" | C:\Users\admin\Desktop\2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 6428 | "C:\Users\admin\Desktop\2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe" | C:\Users\admin\Desktop\2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\VCRUNTIME140.dll | executable | |
MD5:1A84957B6E681FCA057160CD04E26B27 | SHA256:9FAEAA45E8CC986AF56F28350B38238B03C01C355E9564B849604B8D690919C5 | |||
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\_socket.pyd | executable | |
MD5:A092B2DE9E1128F73E26D142A5B2D68B | SHA256:389D2B94A3562879F9E0A17CACE1574EE308AC39A5D9F5659F885284C9B2D19E | |||
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\_hashlib.pyd | executable | |
MD5:2AC2DEE9FDB32BE30FEFD4FDB5D280B3 | SHA256:F10C90062EAA68F41B1A6B34F3796E3AB8E0D765E595236E893CFF9FAD30116A | |||
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\_bz2.pyd | executable | |
MD5:5C952E57426E429F6F4CEC9FEB841815 | SHA256:B682E9E8152036BDEBF4CA5410D3C0F88FA3272A969830F63C7B61BB1F0DA89F | |||
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\_decimal.pyd | executable | |
MD5:FBE8BB3048DF17FF9DDB0972825FDA71 | SHA256:283AA604D532B6239AA8D8794C8D8A4F3A11C93DFBCEF846315CFD74F5E07E2F | |||
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\libcrypto-1_1.dll | executable | |
MD5:4633D62F19C0B25318B1C612995F5C21 | SHA256:47376D247AE6033BC30FEE4E52043D3762C1C0C177E3EC27CA46EFF4B95C69B0 | |||
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\_lzma.pyd | executable | |
MD5:6174470C775AD7529891E1BA3C54F87B | SHA256:E1E346F8B9FA43EC5519166D92625168EBB642A70F52611545117631C74181BD | |||
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\python310.dll | executable | |
MD5:73CADAB187AD5E06BEF954190478E3AA | SHA256:B4893ED4890874D0466FCA49960D765DD4C2D3948A47D69584F5CC51BBBFA4C9 | |||
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\select.pyd | executable | |
MD5:6EBA3E39E61C839818F502BD67BBD672 | SHA256:C942F16C17687E988434813E50D2FB222C528D0E56CCF2D15B13104676F93FC9 | |||
| 5020 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | C:\Users\admin\AppData\Local\Temp\_MEI50202\unicodedata.pyd | executable | |
MD5:73A25EF47977BFF82315023F7F8E9DB1 | SHA256:AC2966C1A1F1FBEE97666E0AAADE5AB960B445AF3BACC1650B83EA8B637F2F7A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 814 b | whitelisted |
2664 | RUXIMICS.exe | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
1268 | svchost.exe | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
1268 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 814 b | whitelisted |
2664 | RUXIMICS.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 814 b | whitelisted |
— | — | POST | 500 | 40.91.76.224:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | whitelisted |
— | — | POST | 500 | 40.91.76.224:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2664 | RUXIMICS.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1268 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6428 | 2025-07-06_34f234d8198274d4424d880395647a0b_amadey_black-basta_elex_luca-stealer.exe | 192.168.1.2:4444 | — | — | — | malicious |
1268 | svchost.exe | 23.53.40.178:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 23.53.40.178:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2664 | RUXIMICS.exe | 23.53.40.178:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1268 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |